Here's the scenario. Your File Integrity Monitoring (FIM) tool alerted you that a new file was written to disk on one of your servers. Other than that, you don't have visibility into anything else associated with this file except its name. Unfortunately, the FIM agent only recorded its name and not its location on disk right before the agent crashed. To start down the path of analyzing this file, we'll use some of our discovery phase tools to locate this file on disk so that we can copy the file to our 32-bit Ubuntu virtual machine lab.
In this recipe, we will use a few of the tools we learned about in the previous chapter to locate the file on disk to prepare it for transfer to our lab. Now, it should be obvious, but we'll use our imagination a bit and actually use these tools on the 32-bit Ubuntu virtual machine we created in Chapter...